# No secret belongs in this repo any more: every credential lives in one shell-level store # (${SHARED_ENV}/tools/secrets.sh), and opencode.json reads it as {env:...}. This line stays as a # backstop, so a workspace-scoped copy that someone re-creates by habit still cannot be committed. .secrets/ # Settings backups inherit the env block — and secrets with it. .claude/settings.local.json.bak* # The default profile parityOverlay copies these primary→worktree, so they appear in EVERY worker # worktree. Two reasons they must be ignored. They hold environment values, which is reason enough. # And since CB-576 a release preserves any worktree that `git status --porcelain` calls dirty — # untracked files included, deliberately. An untracked overlay file would therefore make every # COMPLETED release preserve its worktree, and worktrees would pile up with no error to notice. .env .envrc # Daemon runtime artefacts. fleetd appends its log wherever it is launched from, so both the # repo root and fleetd/ collect one; neither belongs in git. fleetd.out fleetd/fleetd.out logs/ # fleetd #480: the lead rollover handover file. `leadRollover.handoverPath` points here, and the # outgoing lead rewrites it on every rollover. It is a snapshot of one moment's live state — # unpushed branches, running builds, open questions — so it is stale the moment it is written and # has no business in git history. .handover/